re:RPM Verification

From: bigrigdriver (bigrigdriver1L_at_netscape-dot-net.no-spam.invalid)
Date: 10/25/04


Date: 25 Oct 2004 03:09:39 -0500

The signature thing refers to the pgp (or gpgp) signature which
verifies the origin of the file, and, idirectly, it's degree of
integrity. If I'm not mistaken, 'Drake is an rpm based OS? Then, when
you download a package, also d/l the md5 checksum. Before installing,
run 'rpm --checkig <packagename>' to verify it's authinticity.
Signatures are bought and paid for through one of several
authinticating sources. When the signature expires, rpm will not be
able to veriry the source, therefore you get the kind of message you
mentioned.

*-----------------------*
        Posted at:
  www.GroupSrv.com
*-----------------------*



Relevant Pages

  • Re: missing signatures in apt-get
    ... > I have seen this a lot with Mandrake RPMs from a non-Mandrake source. ... > It doesn't stop me from installing with rpm, so I just ignore the message. ... Oh, manyally I can install rpms without signature, no problem, I ...
    (comp.os.linux.misc)
  • RE: "Package is not signed..."
    ... Did you copy the key necessary for verification of package signature to ... I've created an RPM and signed it, and I'm trying to distribute it to ... Downloading headers to solve dependencies... ... The package heartbeat-2.0.5-1 is not signed with a GPG signature. ...
    (RedHat)
  • Re: Verifying RPMs with PGP Signatures
    ... > I'm trying to install dovecot but want to verify the RPM from the site with the given PGP signature. ... The second one is a signature inside the RPM package file. ...
    (RedHat)
  • Re: Livna / RPMFusion updates
    ... Have you noticed that the RPM Fusion GPG key as included in Livna's ... Header V3 DSA signature: OK, ... Header SHA1 digest: OK ...
    (Fedora)
  • Re: [SLE] Cannot install Unsigned Packages using apt-get.
    ... With signature checking, this wouldn't happen. ... just too lazy for real security, which is why the common answer to your ... Oh, and just blindly installing some rpm containing keys, and then ... base java update-drpm update-prpm update extra kde samba3 suser-agirardet ...
    (SuSE)